No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack ironic-python-agent
|
|
| Vendors & Products |
Openstack ironic-python-agent
|
Fri, 24 Jul 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell. | |
| First Time appeared |
Openstack
Openstack ironic Python Agent |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:openstack:ironic_python_agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic Python Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-07-24T12:27:00.582Z
Reserved: 2026-07-24T03:53:11.727Z
Link: CVE-2026-66138
Updated: 2026-07-24T12:26:57.314Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T05:30:05Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')